TACTIC: CREDENTIAL ACCESS

Keylogging (T1056.001): real cases

MITRE Definition ↗
Adversaries record keystrokes to harvest passwords and confidential communications.

Key Facts

Technique ID
T1056.001
Credential Access
Mapped Cases
2
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1056.001.
  • Tactical Phase: Credential Access.
  • Substantiated in 2 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Indictment ¶ 22, Page 12
"Carbanak malware contained keystroke logging modules to capture administrative credentials entered in terminal sessions."
U.S. District Court for the Western District of Washington View full case dossier →
Primary Source Evidence Excerpt: US-CERT Advisory TA14-002A
"Operatives deployed a customized variant of BlackPOS (Kaptoxa) malware across thousands of cash register POS terminals to scrape payment card magnetic stripe tracks from process memory."
U.S. District Court for the District of Minnesota View full case dossier →